Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T17CC2A4305086F8371987B3D0E376A74AB3959788E6034B0A63FDC75D2FCAD44EC2A661 |
|
CONTENT
ssdeep
|
384:TkFwBdh1lImfWbKI6E8WZ7WeI1eIyKTzpi6mm5GZVWs7mBCqIOqZjlOdqz:TkFw/XBa9I0Iv1EX72VQYqz |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
d234ebad14969569 |
|
VISUAL
aHash
|
0000040600fffdfd |
|
VISUAL
dHash
|
96df9cbc9c332321 |
|
VISUAL
wHash
|
0000060e0effffff |
|
VISUAL
colorHash
|
1b002000180 |
|
VISUAL
cropResistant
|
a080c068688080a2,a080c0b030a08092,a080a81a1aa080a2,0800189ada280008,0006686969699620,1b002b2329210103,923fde9c9cac9c98,4cb0f06060e02129 |
• Amenaza: Ataque de phishing dirigido a los usuarios de EvoVerdex.
• Objetivo: Operadores de criptomonedas.
• Método: Sitio web malicioso diseñado para robar credenciales de usuario.
• Exfil: validation/thankyou.php (probablemente).
• Indicadores: Dominio muy nuevo, Javascript ofuscado, formulario que solicita información sensible.
• Riesgo: ALTO
The attackers are using a form to collect user credentials such as email and phone number, which can be used to gain access to a user's accounts.
Pages with identical visual appearance (based on perceptual hash)
Found 2 other scans for this domain